Description
Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with schedule creation permission to execute arbitrary PowerShell code via crafted schedule parameter names concatenated into a script invocation.
Published: 2026-07-24
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw arises from improper control of code generation in the schedule feature of Devolutions PowerShell Universal. An authenticated user who has permission to create a schedule can supply crafted parameter names that are concatenated into a PowerShell script invocation. This allows the user to inject arbitrary PowerShell commands that will execute in the context of the scheduling process, providing the ability to run any code the user wishes.

Affected Systems

Devolutions PowerShell Universal versions 2026.2.2 and earlier are affected. The vulnerability exists specifically in the scheduling component of the product for any installation of these earlier releases.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity impact with the potential for full system compromise. The EPSS score of less than 1% implies that the probability of exploitation is currently very low, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation. However, because the vulnerability requires authentication and schedule‑creation privileges, the attack vector is likely an internal privileged user who can create a malicious schedule. If an attacker gains such credentials, they could execute arbitrary PowerShell code with the permissions of the scheduling engine, potentially compromising the host and any network resources visible to that process.

Generated by OpenCVE AI on August 3, 2026 at 20:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest available release of Devolutions PowerShell Universal that includes the schedule code‑generation fix.
  • Restrict schedule creation permission to only trusted users and review current user privileges to minimize the attack surface.
  • If the scheduling feature is not required, disable it entirely to eliminate the risk of code injection.

Generated by OpenCVE AI on August 3, 2026 at 20:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Title PowerShell Code Injection via Schedule Parameter Names in Devolutions PowerShell Universal

Sun, 02 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Title PowerShell Code Injection via Schedule Parameter Names in Devolutions PowerShell Universal

Sat, 01 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
Title Authenticated Code Injection via Malicious Schedule Parameter in Devolutions PowerShell Universal

Sun, 26 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title Authenticated Code Injection via Malicious Schedule Parameter in Devolutions PowerShell Universal

Sat, 25 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Devolutions
Devolutions powershell Universal
Vendors & Products Devolutions
Devolutions powershell Universal

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with schedule creation permission to execute arbitrary PowerShell code via crafted schedule parameter names concatenated into a script invocation.
Weaknesses CWE-94
References

Subscriptions

Devolutions Powershell Universal
cve-icon MITRE

Status: PUBLISHED

Assigner: DEVOLUTIONS

Published:

Updated: 2026-07-24T17:43:24.583Z

Reserved: 2026-07-23T19:24:57.616Z

Link: CVE-2026-16800

cve-icon Vulnrichment

Updated: 2026-07-24T17:42:45.611Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-24T15:17:12.963

Modified: 2026-07-29T20:33:43.027

Link: CVE-2026-16800

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T20:15:04Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')